CVE-2025-69233Medium· 6.5▾ SunlitDue to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of the platform are able to exceed the allocation limits configured for their accounts/domai…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Due to multiple time-of-check time-of-use race conditions in the resource count check and increment logic, as well as missing validations, users of the platform are able to exceed the allocation limits configured for their accounts/domains. This can be used by an attacker to degrade the infrastructure's resources and lead to denial of service conditions.
Users are recommended to upgrade to Apache CloudStack versions 4.20.3.0 or 4.22.0.1, or later, which fixes this issue.
cloudstack >= 4.0.0, < 4.20.3.0cloudstack >= 4.21.0.0, < 4.22.0.1Upgrade past the affected range:
cloudstack 4.22.0.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-66171Medium· 6.5The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0
CVE-2025-66172High· 8.1The CloudStack Backup plugin has an improper access logic in versions 4.21.0.0 and 4.22.0.0
CVE-2025-66467High· 8.0Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned
CVE-2025-66170Medium· 6.5The CloudStack Backup plugin has an improper authorization logic in versions 4.21.0.0 and 4.22.0.0
CVE-2026-23950High· 8.8node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3
CVE-2026-91865High· 7.5A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgr…